Buffer Overflow Vulnerability in Linux Kernel SMB Client
CVE-2026-64598

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
6 August 2026

What is CVE-2026-64598?

A vulnerability in the Linux kernel's SMB client could lead to a crash due to an invalid error pointer dereference when handling the '*num_sgs' variable. This issue arises from improper error code management in the 'smb2_aead_req_alloc()' function, where an expected integer conversion is not correctly applied. As a result, under certain conditions, this flaw can trigger system instability, emphasizing the importance of timely updates and patches to maintain system integrity.

Affected Version(s)

Linux d08089f649a0cfb2099c8551ac47eef0cc23fdf2

Linux d08089f649a0cfb2099c8551ac47eef0cc23fdf2

Linux d08089f649a0cfb2099c8551ac47eef0cc23fdf2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.